CVE-2014-8008

Cisco Unified Communications Manager - Authenticated Absolute Path Traversal via RTMT API

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8008. PoCs published by Bernhard Mueller.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in Cisco Unified Communications Manager, including Shellshock command injection, Local File Inclusion, unauthenticated ping access, and a magic session ID bypass. It provides technical descriptions and example commands but does not include functional exploit code.

Description

Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.

Exploits (1)

exploitdb WRITEUP
by Bernhard Mueller · textwebappsmultiple
https://www.exploit-db.com/exploits/37816

This advisory details multiple vulnerabilities in Cisco Unified Communications Manager, including Shellshock command injection, Local File Inclusion, unauthenticated ping access, and a magic session ID bypass. It provides technical descriptions and example commands but does not include functional exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Cisco Unified Communications Manager <9.2, <10.5.2, <11.0.1
Auth required
Prerequisites: valid user account for some exploits · network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72263
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031604
Various Sources vendor-advisory x_refsource_cisco
https://tools.cisco.com/security/center/viewAlert.x?alertId=37111

Scores

EPSS 0.0844
EPSS Percentile 94.3%

Details

CWE
CWE-200
Status published
Products (1)
cisco/unified_communications_manager
Published Jan 22, 2015
Tracked Since Feb 18, 2026